Which of the following is the primary objective of a rootkit?
A.
It provides an undocumented opening in a program
B.
It replaces legitimate programs
C.
It creates a buffer overflow
D.
It opens a port to provide an unauthorized service
The Answer Is:
B
This question includes an explanation.
Explanation:
The correct answer is B, It replaces legitimate programs. A rootkit is malicious software used after compromise to hide the attacker’s presence, maintain privileged access, and avoid detection. CEH-aligned material describes rootkits as tools that obscure system compromise by replacing or substituting administrator utilities with modified versions that hide malicious activity. Linux rootkit material also states that rootkits contain replacement executables for critical operating system components, used to hide evidence and provide backdoor access. Therefore, among the options, replacing legitimate programs is the best match. Option A describes a backdoor concept more generally. Option C describes a vulnerability/exploitation condition, not a rootkit’s purpose. Option D may describe one possible backdoor behavior, but it is not the primary rootkit objective. Rootkits commonly hide files, processes, registry entries, logs, and malicious services, making detection and removal difficult.
312-50v13 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"